Skip to content

[YUNIKORN-3435] Upgrade go dependencies for CVEs - #1140

Draft
PoiBlackTea wants to merge 2 commits into
apache:masterfrom
PoiBlackTea:YUNIKORN-3435
Draft

[YUNIKORN-3435] Upgrade go dependencies for CVEs#1140
PoiBlackTea wants to merge 2 commits into
apache:masterfrom
PoiBlackTea:YUNIKORN-3435

Conversation

@PoiBlackTea

Copy link
Copy Markdown
Contributor

Description

Upgrade go dependencies for CVEs

Type of change

Please delete options that are not relevant.

  • Bug Fix
  • Improvement
  • Feature
  • Refactoring
  • Documentation

Jira issue

Jira ID : https://issues.apache.org/jira/browse/YUNIKORN-3435

  • I have created a Jira issue for this pull request.
  • The Jira ID is part of the title of this pull request.

AI Tooling

If an AI tool was used:

  • The PR includes the phrase "Generated by Antigravity CLI", where Antigravity CLI is the name of the AI tool used.
  • My use of AI contributions follows the ASF legal policy.

Check https://www.apache.org/legal/generative-tooling.html for details.

How has this been tested?

  • New unit tests were added to cover new or changed code paths.
  • make test_all was run, and no failures reported.
  • A pull request will be opened for new e2e tests (apache/yunikorn-k8shim repository).

Questions:

  • The change needs documentation, a pull request for apache/yunikorn-site repository will be created.
  • There is breaking changes for older versions: jira is tagged with release-notes label.
  • The licenses files needs to be updated.

Screenshots or other details

NA

@codecov

codecov Bot commented Aug 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.69%. Comparing base (41ae1cc) to head (4e0f445).

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #1140      +/-   ##
==========================================
+ Coverage   81.64%   81.69%   +0.04%     
==========================================
  Files         104      104              
  Lines       14402    14402              
==========================================
+ Hits        11759    11766       +7     
+ Misses       2352     2347       -5     
+ Partials      291      289       -2     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@chenyulin0719
chenyulin0719 self-requested a review August 30, 2026 13:22
@manirajv06
manirajv06 self-requested a review August 31, 2026 05:50

@manirajv06 manirajv06 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SI changes have gone in. Can you update the SI version?

@PoiBlackTea
PoiBlackTea requested a review from manirajv06 August 31, 2026 12:20
@PoiBlackTea

Copy link
Copy Markdown
Contributor Author

SI changes have gone in. Can you update the SI version?

Since the official golang.org/x/crypto security release (for CVE-2026-56855 & CVE-2026-78662) is scheduled for this Wednesday (Sept 2), if it's not urgent, I've converted this PR to Draft for now.I will update both the SI version and the new x/crypto version together once the official tag is released on Sept 2, and then mark it ready for review. Thanks!

[security] golang.org/x/crypto fix pre-announcement

@PoiBlackTea
PoiBlackTea marked this pull request as draft August 31, 2026 13:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants